Software Security Engineer

Wolfe, LLC

Pittsburgh (Allegheny County)

On-site

USD 110,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Restricted Stock Units (RSUs)
Profit Share and/or Incentive Bonus
Medical, Prescription, Vision, and Dental insurance
Short-Term and Long-Term Disability Insurance
PTO (vacation and sick time)
401(k) plan

Job summary

Wolfe, LLC is seeking an Application Security Engineer to embed security within software development processes in Pittsburgh, PA. The role is integral to building financial products with a focus on AI integration. Responsibilities include performing code reviews, managing vulnerabilities, and enhancing security protocols.

This is a full-time onsite position that offers extensive learning opportunities in enterprise security tooling with mentorship and support for certifications.

Qualifications

  • 2+ years in application security, DevSecOps, or software development with security exposure.
  • Real coding background with knowledge of secure coding principles.
  • Hands-on exposure to CI/CD pipelines and security tooling.

Responsibilities

  • Perform code reviews and testing.
  • Integrate automated security tooling within CI/CD pipelines.
  • Manage vulnerability management and Bug Bounty program.
  • Operate and improve Bot Management and API security controls.
  • Promote secure coding standards and measure DevSecOps maturity.

Skills

Application security
DevSecOps
Secure coding principles (OWASP Top 10)
CI/CD pipelines
Vulnerability management
Communication skills

Education

Bachelor's in Information Security, Cybersecurity, Computer Science, or related field

Tools

GitHub
GitLab
Jenkins
AWS DevOps

Job description

Application Security Engineer

Department: Security

Employment Type: Full Time

Location: Pittsburgh, PA

Compensation: $110,000 - $120,000 / year

Description

About Wolfe

Recognized among Pittsburgh's 2024 Top Workplaces and Fastest-Growing Companies, Wolfe has been a leader in the Gift Card and FinTech sectors for over 25 years. We partner with national brands such as Pizza Hut, KFC, Pandora Jewelry, Kendra Scott, Wawa, Journeys and others to manage their gift card programs. Our flagship consumer brand, PerfectGift.com, enables customers to create customized gift cards. We are a fast-paced environment, like kayaking down a white-water river, not canoeing on a lake.

About The Role

Wolfe is a Pittsburgh-based FinTech company building the next generation of financial products, and we are actively embedding AI across our product, our internal processes, and the way our teams work day-to-day. As an Application Security Engineer, you'll work hands‑on alongside developers and DevOps engineers to build security into how we ship software — reviewing code, improving AI agent behaviors, hardening CI/CD pipelines, and helping teams find and fix vulnerabilities across application code, containers, and cloud infrastructure. This role is built for growth: whether you're a developer moving into security or an early‑career security engineer expanding into application security, you'll learn enterprise security tooling — including AI/ML and LLM-powered tools — with support to earn certifications and grow alongside a security team that mentors in person.

We're looking for candidates who are enthusiastic about an in‑office culture. This is a 5‑day onsite role in Pittsburgh, PA.

Responsibilities
  • Perform code reviews, SAST/DAST testing, basic penetration tests, and basic threat modeling, and work with developers to remediate vulnerabilities across application code, libraries, containers, and infrastructure as code.
  • Integrate and run automated security tooling (such as Snyk, SemGrep, or Cycode) within CI/CD pipelines across code repositories (such as GitHub, GitLab, Jenkins, or AWS DevOps), and help automate findings triage and reporting.
  • Manage a vulnerability management program, vulnerability scanning tools and the enterprise Bug Bounty program, tracking and prioritizing remediation against defined SLAs.
  • Help operate and improve Bot Management, WAF, secrets management, and API security controls across Wolfe's applications.
  • Apply and promote secure coding standards aligned to OWASP and SANS CWE Top 25, and contribute to measuring DevSecOps maturity using a framework such as DSOMM or BSIMM.
  • Partner with developers, security operations, product management, and incident response teams, sharing secure-coding and vulnerability‑management practices as you grow your own expertise.
Impact Statement
  • Update existing Application Security Strategy and make improvements on monitoring and reporting on KPI’s
  • Make a significant improvement to least one automated security tool (DAST, SAST, SCA, or container scanning) in the production CI/CD pipeline, with results feeding a documented triage workflow.
  • Driving additional Bug Bounty submissions and improve bot management turning & protections prior to end of Q3.
  • Provide product and technology advisement and testing for new application and AI functionality
  • Develop and plan a purposeful Application and AI development training program
Qualifications
  • 2+ years of experience in application security, DevSecOps, or software development with security exposure — including developers looking to move into a dedicated security role — plus a Bachelor's in Information Security, Cybersecurity, Computer Science, or a related field (equivalent experience accepted in lieu of a degree).
  • A real coding background and working knowledge of secure coding principles (OWASP Top 10, SANS CWE Top 25).
  • Some hands‑on exposure to CI/CD pipelines (GitHub, GitLab, Jenkins, or AWS DevOps) and an interest in integrating security tooling into them.
  • Strong verbal and written communication skills, with the ability to explain security concepts to both technical and non‑technical teammates.
  • Eagerness to learn enterprise security tooling (vulnerability scanners, Bot Management, SAST/DAST/SCA) and maturity frameworks like DSOMM or BSIMM — deep prior experience with these is a plus, not a requirement.
  • No certifications required; experience with CISSP, OSCP, GCSA, AWS Security Specialty, or CSSLP is a plus, and we'll support you in earning them.
Compensation, Benefits, and Perks

Wolfe is committed to providing a comprehensive benefits package to support your well‑being, along with competitive compensation. Our benefits and perks include but not limited to:

  • Restricted Stock Units (RSUs)
  • Profit Share and/or Incentive Bonus
  • Medical, Prescription, Vision, and Dental insurance for employees and dependents (Wolfe pays 80% of premium)
  • Short‑Term Disability Insurance (Wolfe pays 100% of premium)
  • Voluntary Long‑Term Disability Insurance, Life Insurance, Critical Illness Insurance, Accident Insurance, and Hospital Indemnity coverage
  • PTO (vacation and sick time)
  • Corporate Holidays and Floating Holidays
  • 401(k)
  • Employee recognition program
  • Charitable Donation to a charity of your choice yearly
  • Employee Referral Bonus
  • Tuition Reimbursement
  • Internal Training and Information sessions
  • Family Picnic, Holiday Party, and other outings
  • Internal Culture Club
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Analyst
Senior GRC Analyst

Wolfe,-LLC-1 • Pittsburgh

On-site
USD 114,000 - 163,000
RSUs
Profit Sharing
Medical Insurance
+5
Senior Brand Manager
Senior Brand Manager

Wolfe,-LLC-1 • Pittsburgh

On-site
USD 128,000 - 173,000
Senior Vice President, Product Management
Senior Vice President, Product Management

Telos Gifting LLC • Pittsburgh

On-site
USD 210,000 - 250,000
Restricted Stock Units (RSUs)
Profit Share
Management Incentive Plan
+7
VP, Data Platform and Knowledge
VP, Data Platform and Knowledge

Wolfe, LLC • Pittsburgh

On-site
USD 200,000 - 226,000
Restricted Stock Units (RSUs)
Incentive Bonus
Profit Share
+4
Senior UX Designer
Senior UX Designer

Wolfe, LLC • Pittsburgh

On-site
USD 130,000 - 140,000
RSUs
Profit Sharing
Medical, Vision, Dental insurance
+12
Data Engineer
Data Engineer

Wolfe,-LLC-1 • Pittsburgh

On-site
USD 75,000 - 85,000
RSUs
Profit sharing
Medical Insurance
+7
Product Security Engineer
Product Security Engineer

United States Digital Space LLC • United States

Hybrid
USD 120,000 - 160,000
Medical/Rx Insurance
401(k) Retirement Savings Plan
Employee Stock Participation Plan
+1
Onsite App Security Engineer — Growth & AI Tools
Onsite App Security Engineer — Growth & AI Tools

Wolfe, LLC • Pittsburgh

On-site
USD 110,000 - 120,000
Restricted Stock Units (RSUs)
Profit Share and/or Incentive Bonus
Medical, Prescription, Vision, and Dental insurance
+3
Senior Digital Marketing Manager
Senior Digital Marketing Manager

Wolfe, LLC • Pittsburgh

On-site
USD 100,000 - 140,000
RSUs
Profit sharing
Health insurance
+1
Staff Application Security Engineer
Staff Application Security Engineer

Upside • Washington

Hybrid
USD 210,000 - 230,000
Medical, dental, and vision coverage starting on Day 1
Equity (ISOs)
401(k) program
+2